Trust Centre
Security, privacy and data integrity
AmpRegs AI handles regulated electrical compliance records. This page summarises the controls we apply. It is maintained by our team and is not an independent certification.
Authentication & access control
Sign-in is handled by Supabase Auth. Every request to our backend is verified server-side. Sensitive routes are protected and authorisation is checked on the server — never relying on hidden UI alone.
Row-level security
Database tables enforce Row-Level Security policies. Users can only read or write records they are entitled to. Cross-organisation access is denied by default.
Certificate integrity
Issued certificates are immutable. Revisions and audit history are append-only. Any amendment after issue produces a new revision and a new PDF — previous versions remain available.
Auditability
Significant actions — creation, modification, submission, approval, issue, archive, ownership transfer and role changes — are recorded so they can be reviewed later.
Encryption in transit
All traffic between your device and AmpRegs AI is served over HTTPS. Files in storage are accessed via short-lived signed URLs rather than public links.
Responsible disclosure
Found a security issue? Please email support@ampregs.com with details so we can investigate. Do not exploit findings against other users' data.